PMOS PCOS privacy

How Period Apps Handle Your Data: A PMOS Privacy Guide

Published by PMOS Vera

How Period Apps Handle Your Data: A PMOS Privacy Guide

In plain terms: This post compares how six period tracking apps handle health data with PMOS (formerly PCOS): Flo, Clue, AskPCOS, Bearable, Euki, and Vera, our own app. No scare stories, just what each app publishes about itself. Every fact comes from each app’s own labels and policies, as of July 4, 2026.

Feature lists get most of the attention when you pick a tracker, and our 2026 roundup of cycle tracking apps for PMOS covers those. Privacy deserves its own calm look, because the answers vary more than you might expect. Here’s what each app says about your data, in its own published words.

Why app privacy is worth a look

Cycle data is personal, and with PMOS you often log more than bleeding days: mood, sleep, medications, labs, the whole-body picture. It’s reasonable to want to know where all of that goes. The good news is that every app in this post publishes an answer.

There’s one legal point worth knowing, and it’s a quiet one. The main US health-privacy law, HIPAA, generally applies to doctors, hospitals, health plans, and insurers. It doesn’t cover most consumer health apps, as the FTC explains in its consumer guidance on health apps.

That’s not a reason for alarm. It simply means an app’s own privacy label and privacy policy are your main window into what it does with your data. So let’s learn to read them, then look at each app.

How to read an App Store privacy label

Every iOS app listing carries an App Privacy section with up to three groups, and Apple defines each one precisely on its privacy labels page:

  • Data Used to Track You: “The following data may be used to track you across apps and websites owned by other companies.” (the standard wording shown on App Store listings)
  • Data Linked to You: “The following data may be collected and linked to your identity.”
  • Data Not Linked to You: data that may be “collected but it is not linked to your identity.”
  • Data Not Collected: “The developer does not collect any data from this app.”

Two nuances matter. First, labels are self-reported by developers, and App Store listings note the information has not been verified by Apple. Second, Apple’s developer rules say data “processed only on device is not ‘collected’ and does not need to be disclosed.”

That second point explains why fully on-device apps can carry the lightest labels. Keep both nuances in mind as we go.

What does Flo publish about your data?

Flo stores your data in the cloud, with an account by default. Its App Store label lists purchases, location, identifiers, and usage data under “Data Used to Track You” (as of July 4, 2026). Its standout privacy feature is Anonymous Mode, which Flo has open-sourced.

The label’s “Data Linked to You” section is broad: health and fitness, purchases, coarse location, email and name, user content, search history, identifiers, usage data, sensitive info, and crash data.

Anonymous Mode is the genuinely notable part. Per Flo’s newsroom, it lets you use the app without your name, email address, or technical identifiers being associated with your health data. It’s built on a protocol called Oblivious HTTP, and Flo published the feature’s code openly. Among cloud-based trackers, that’s an unusual and meaningful option.

Where does Clue keep your data?

Clue stores your data on servers in the European Union, and an account is required. Its privacy policy, dated May 20, 2026, states that “the sensitive health data you track in the Clue app is never shared with or sold to advertisers.” Deletion is handled by email, within one month.

The account asks for a username, date of birth, and email. Clue’s policy says it uses only AWS data centers in the European Union. De-identified data may go to research partners, but only if you switch on an explicit consent toggle.

On the App Store label, identifiers appear under “Data Used to Track You.” Linked to you: health and fitness, coarse location, contact info, user content, identifiers, usage data, and sensitive info. Diagnostics are collected but not linked.

To delete your data, you email trust@helloclue.com, and Clue says it’s deleted “within 1 month.” The clear never-sold sentence and the consent-gated research sharing are Clue’s honest strengths here.

How private is AskPCOS from Monash?

AskPCOS, the free app from Monash University (AskPMOS on the web), has no “Data Used to Track You” section on its App Store label at all (as of July 4, 2026). An account is needed only for certain features, and most of its information is available without one.

The label does list data linked to you: health and fitness, contact info (email, name, and phone number), user content, and a user ID. Not linked to you: coarse location, browsing history, usage data, and performance diagnostics.

Its privacy policy is governed by Victorian privacy law in Australia, and says: “We may use de-identified data to further PCOS research to help us understand the condition better…” For access and correction, the policy points to Monash’s data protection officer at dataprotectionofficer@monash.edu. A university-run app with a simple privacy label is a genuinely reassuring combination.

What does Bearable say about selling data?

Bearable’s policy is direct: “Bearable does not and will never sell any personal data” (Bearable privacy policy). Your entries live in the cloud, in a Firestore database, encrypted before storage, in the EU-West3 region in Frankfurt, Germany. That’s per its privacy policy, last updated February 6, 2025.

An account is an email and password, used for backup. On the App Store label, contact info and identifiers appear under “Data Used to Track You” (as of July 4, 2026). The label and the policy are both Bearable’s own published statements, so read them together.

Deletion is friendly: Bearable says data is deleted “within 30 days” via support@bearable.app, export is available, and the App Store copy says you can export or delete from within the app. Bearable is a UK company registered with the UK Information Commissioner’s Office. The plain never-sell sentence plus in-app export and deletion are real strengths.

Does Euki collect any data at all?

No. Euki’s App Store label reads “Data Not Collected,” which Apple defines as “The developer does not collect any data from this app” (as of July 4, 2026). Euki says your data “is stored locally (on your device) and nowhere else,” with no account, email, or phone number.

Its privacy policy states: “We do not collect any personally identifiable or other information through your use of the App.” An optional PIN protects the app, and Euki doesn’t record it, so losing the PIN means losing access.

You can delete your data on the spot or schedule regular sweeps, per its App Store listing. And per Mozilla’s review, an emergency code shows a fake screen instead of your data. The app is open source and run by a nonprofit. Mozilla’s Privacy Not Included review, dated 2022, praised Euki and gave it no warning label. For a free tracker, this is about as light a footprint as it gets.

How does Vera, our own app, compare?

Vera is our app, so read this section knowing that. Everything you log in the Vera app stays only on your iPhone, in a database encrypted with SQLCipher (AES-256), with the key in the iOS Keychain. There’s no account, no cloud sync, and no Vera server (as of July 4, 2026).

Photos in the journal are individually encrypted with AES-256-GCM. With your permission, Vera reads sleep, steps, and period data from Apple Health to enrich your own history. It never writes back and never transmits Apple Health data.

One thing Vera does send, if you allow it: optional anonymous diagnostics (crash, error, and performance reports) to Sentry in the EU. These carry no health content, no identity, and no IP, and you can switch them off in Settings → Privacy & Data.

An honest note on labels: by Apple’s own developer definition, on-device-only data isn’t “collected,” which is why on-device apps like Euki and Vera can carry the lightest labels. And where a competitor is the better pick, plainly: on Android, Euki is the free on-device option, and among cloud apps, Flo’s Anonymous Mode makes it notable.

How do the six apps compare on privacy?

AppWhere data livesAccountApp Store privacy labelDeletion pathStandout privacy feature
FloCloudYes, by defaultPurchases, location, identifiers, usage dataNot covered here; check Flo’s current policyAnonymous Mode (open-sourced)
ClueEU servers (AWS)RequiredIdentifiersEmail trust@helloclue.com; “within 1 month”Never-sold statement; research sharing needs a consent toggle
AskPCOSCloud, per its labelOnly for certain featuresNone listedAccess and correction via Monash’s data protection officerNo matching section on its label
BearableEU cloud (Frankfurt), encrypted before storageEmail + password (for backup)Contact info, identifiersIn-app, or email support; “within 30 days”Explicit never-sell statement; in-app export
EukiOn the device onlyNoneNone; label reads “Data Not Collected”Delete on the spot or schedule sweepsPIN plus fake-screen emergency code
PMOS Vera (ours)On your iPhone onlyNoneSee the live App Store listingData exists only on your phoneEncrypted database (SQLCipher), key in the iOS Keychain

The five competitor rows reflect each app’s published label and policy as of July 4, 2026. Vera’s row describes how the app is built; for its current label, check the live App Store listing.

Frequently asked questions

What does “Data Not Collected” mean on a privacy label?

It’s Apple’s lightest label, defined as “The developer does not collect any data from this app” (Apple). One nuance: Apple’s developer rules say data processed only on the device doesn’t count as “collected,” so fully on-device apps naturally qualify for this label.

Do period tracking apps have to follow HIPAA?

Generally, no. HIPAA covers doctors, hospitals, health plans, and insurers, not most consumer health apps, per the FTC’s consumer guidance. That’s why an app’s own privacy label and policy are the main way to know how it handles your data.

Which period trackers store data only on the phone?

Among the six apps here, two: Euki and Vera, as of July 4, 2026. Euki is free, on iOS and Android, with a “Data Not Collected” label. The Vera app is iOS-only and keeps everything in an encrypted database on your iPhone, with no account or cloud.

Are privacy labels checked by Apple?

No. Labels are self-reported by developers, and App Store listings note the information has not been verified by Apple (visible on any listing, for example Flo’s). So it’s worth reading the label and the privacy policy together, the way we’ve done in this post.

Policies change, so check the date

Everything above reflects what these six apps published as of July 4, 2026. Privacy policies get revised, labels get updated, and features come and go. Before you commit to an app, take two minutes to open its current App Store listing and skim its privacy policy. The calm habit of checking the source beats any comparison post, including this one.

A note on medical advice

This post is general information about app privacy practices, not medical advice, and it can’t diagnose anyone or guide treatment. For anything about your own health or care, please speak with a qualified healthcare professional who knows your history.

Sources

This article is general information and is not medical advice. For anything about your own health, talk with a qualified healthcare professional.

Vera now speaks PMOS too.

Get the app: free to track, private by design, on iOS.

Get Vera